""ET EXPLOIT Sangoma Asterisk Originate AMI RCE (CVE-2019-18610) (PoC Based)""

SID: 2035014

Revision: 1

Class Type: attempted-admin

Metadata: created_at 2022_01_28, cve CVE_2019_18610, deployment Perimeter, deployment Internal, signature_severity Major, updated_at 2022_01_28

Reference:

  • cve

  • 2019-18610

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: any

Destination Port: any

Flow:

Contents:

  • Value: "Action|3a 20|Originate"

  • Value: "Data|3a|"

  • Value: "|20|/tmp/"

Within: 45

PCRE:

Special Options:

  • nocase

  • fast_pattern

  • nocase

  • nocase

source